Researchers Claim 400,000+ MikroTik Routers Infected With Mining Malware

- Advertisement -

December 7, 2018 12:36 AM

MikroTik mining malware was first discovered in Brazil in August, but the virus continues to spread all over the world.

Malware that specifically targets MikroTik routers could now be affecting more than 415,000 routers across the globe, according to a December 2 tweet from VriesHD.

The malware, which typically uses software to secretly mine Monero, was first discovered in Brazil in August.

According to Bad Packets LLC, a security research firm, over 170,000 routers in Brazil were infected with the mining malware. Security researcher Simon Kenin of cybersecurity firm Trustwave described the attack by saying:

“The attacker wisely thought that instead of infecting small sites with few visitors or finding sophisticated ways to run malware on end-user computers, they would go straight to the source: carrier-grade router devices.”

According to Bad Packets, the epidemic is spreading – by August 25, those infected included approximately 3,000 MikroTik routers in the US containing IP addresses assigned to internet service provider Cogent. A month later, over 600 routers belonging to the Douglas County Public Utility District in north-central Washington state were infected with the malware. According to Bad Packets, “39% of the IPs they manage route to a compromised device.”

While research shows that Coinhive is used in most of these instances, during the largest “campaign” CoinImp software was used to infect 115,000 routers. And in September, Bad Packets pointed out more malware targeting MikroTik routers, this one injecting MinerAlt software, which is also used to mine Monero, to steal 30 percent of users’ mining revenue. To avoid detection, “Infected routers in this campaign are configured to throttle the CPU usage of the victims’ devices… the amount of CPU power used for mining cryptocurrency is roughly 80%.”

Although those responsible for the malware cleverly evolve their methods to circumvent discovery, there is at least one patch victims, internet services providers, and MikroTik router owners can use to protect themselves. And it was actually released way back in April. MikroTik’s patch, which intended to “fix a zero-day vulnerability exploited in the wild,” was released after users of a Czech tech forum spotted malware mining attacks targeting a remote management service called Winbox, which is included with all MikroTik routers. The service allows users to configure devices.

However, even after multiple warnings to upgrade routers – from MikroTik and security researchers, a large number of devices could still be infected. According to a September tweet from Bad Packets, several hundred thousand hosts were still compromised. 

Describing the challenge of upgrading one’s router, a researcher from VriesHD told Hard Fork:

“Users should indeed update their routers, yet the biggest bunch of them are distributed by ISPs to their customers, who often have no idea what to do or how to update the router. Often these distributed routers are limited in their rights as well, not allowing users to update the routers themselves. The patch for this specific problem has been out for months and I’ve seen ISPs with thousands of infections disappear from the list. Unfortunately, it appears tons of ISPs simply won’t take action to mitigate the attacks.”

Nathan Graham is a full-time staff writer for ETHNews. He lives in Sparks, Nevada, with his wife, Beth, and dog, Kyia. Nathan has a passion for new technology, grant writing, and short stories. He spends his time rafting the American River, playing video games, and writing.

Like what you read? Follow us on X @Bitnewsbot to receive the latest MikroTik, Monero or other Ethereum technology news.



Previous Articles:

- Advertisement -
- Advertisement -
- Advertisement -

Latest

Solo Bitcoin Miner Hits Jackpot, Scores $266,000 With Single Block

A solo Bitcoin miner secured block 888,737 and earned approximately $266,000 in rewards, consisting of 3.125 BTC plus transaction fees.The miner reportedly used a...

Ex-SEC Official Rejects Crypto Regulatory Reform at SEC Roundtable

Former SEC official John Reed Stark opposes regulatory reform for cryptocurrencies at the SEC's first crypto roundtable.Stark argues crypto buyers are investors who need...

Open House Group Adds XRP, SOL, DOGE to Crypto Payment Options in Japan

Open House Group expands cryptocurrency payment options to include XRP, Solana, and Dogecoin alongside existing Bitcoin and Ethereum options.The company launches a Traditional Chinese...

Chainlink CCIP Breaks Vendor Lock-In Barrier for Cross-Chain Tokens

ChainLink CCIP provides token issuers with cross-chain functionality without being restricted to a single blockchain ecosystem.Cross-Chain Tokens (CCTs) enable seamless token movement across multiple...

Michael Saylor raises $722.5M for bitcoin buys at premium dividend rates

Strategy (formerly MicroStrategy) increased its fundraising from $500M to $722.5M but had to offer significantly more favorable terms to investors.The STRF preferred stock was...

Tether in Talks with Big Four Accounting Firm for Independent Audit

Tether is in discussions with one of the Big Four accounting firms to conduct an independent audit of its stablecoin reserves.The stablecoin issuer has...

SEC Finally Opens Door to Crypto Industry Collaboration on Regulations

SEC's Crypto Task Force, led by Commissioner Hester Peirce, held its first roundtable focused on developing a regulatory framework for digital assets.Acting Chairman Mark...

Coinbase in Advanced Talks to Acquire Crypto Derivatives Giant Deribit

Coinbase is in advanced discussions to acquire Deribit, potentially valuing the world's largest cryptocurrency derivatives exchange at $4-5 billion.The acquisition would expand Coinbase's derivatives...
- Advertisement -

Must Read

How to Buy VPS with Crypto from Hostinger – Step by Step guide

Did you know that nowadays you can use Bitcoin to purchase a Windows VPS? If you’re here, you’re probably wondering how to do it....

Read Next
Recommended to you